Reply to post:

Card-stealing code that pwned British Airways, Ticketmaster pops up on more sites via hacked JS

phuzz Silver badge

I'd always imagined that the 3rd party code had been downloaded, checked and installed.

Even if it was being run off their servers, can you imagine the conversation?

developer, running into the room: We need to update foo.js to version

sysadmin: Have you checked that it's got no security issues?

developer: Marketing want us to have the flibble text flashing and the new version of foo reinstates the blink tag. They want it live half an hour ago because they've already got the adverts running.

sysadmin: I really think we should test this...

developer: No time, just put it live!

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon